Forum Index > Open Source > Помогите с natd

#0 by attiny (Power User) (0 mesaje) at 2007-09-18 08:21:16 (866 săptămâni în urmă) - [Link]Top
проблема с нат-ом. если я использую ipnat то все работает ок, а вот natd не хочит работать

вот мои параметры ядра которые я добавил:

options IPFIREWALL
options IPFIREWALL_VERBOSE
options IPFIREWALL_VERBOSE_LIMIT=100
options IPFIREWALL_DEFAULT_TO_ACCEPT
options IPFIREWALL_FORWARD
options IPDIVERT
options DUMMYNET
options TCP_DROP_SYNFIN
options HZ=1000

/etc/rc.conf:

gateway_enable="YES"
defaultrouter="87.248.XXX.1"
hostname="eci.starnet.md"
ifconfig_rl0="DHCP"
ifconfig_rl1="inet 192.168.0.1  netmask 255.255.255.0"
inetd_enable="YES"
keymap="us.iso"
linux_enable="YES"
sshd_enable="YES"
http_enable="YES"
mysql_enable="YES"
mrtg_daemon_enable="YES"
proftpd_enable="YES"
apache22_enable="YES"
kern_securelevel_enable="NO"

natd_enable="YES"
natd_interface="rl0"
natd_flags="-f /etc/natd.conf"

firewall_enable="YES"
firewall_script="/etc/rc.firewall"

/etc/natd.conf:

#rdesktop forward
redirect_port tcp 192.168.0.2:3389 3389

/etc/rc.firewall:

cmd="ipfw -q add"
ipfw -q -f flush

$cmd allow all from any to any via lo0
$cmd deny all from any to 127.0.0.0/8
$cmd deny all from 127.0.0.0/8 to any
$cmd deny tcp from any to any frag

$cmd add divert natd all from any to any via rl0

$cmd allow all from me 22 to any
$cmd allow all from any to me 22
$cmd allow icmp from me to any
$cmd add allow icmp from any to me

$cmd check-state
$cmd allow icmp from any to any

$cmd 1200 allow all from 192.168.0.2 to any
$cmd 2200 allow all from any to 192.168.0.2

$cmd 1300 allow all from 192.168.0.3 to any
$cmd 2300 allow all from any to 192.168.0.3

$cmd 1400 allow all from 192.168.0.4 to any
$cmd 2400 allow all from any to 192.168.0.4

$cmd pipe 1 config bw 5000Kbit/s
$cmd pipe 2 config bw 2000Kbit/s
$cmd queue 1 config pipe 1 weight 50 mask dst-ip 0x00000000
$cmd queue 2 config pipe 2 weight 50 mask dst-ip 0x00000000
$cmd add 100 queue 1 ip from any to 192.168.0.0/24 80,21,5190...и.т.д.
$cmd add 200 queue 2 ip from 192.168.0.0/24 80,21,5190...и.т.д. to any

$cmd allow tcp from any to any 33633
$cmd allow udp from any to any 33633

$cmd deny log all from any to any

Плиз подскажите что я сделал криво, и как нужно сделат ь правильно


Mesaj util ?   Da   0 puncte

1
<< Precedenta      Următoarea >>

#1 by aylyn Volei Club (Алина Ивановна) (0 mesaje) at 2008-01-07 06:55:45 (850 săptămâni în urmă) - [Link]Top
:smoke:



Mesaj util ?   Da   0 puncte
#2 by raven4 (User) (0 mesaje) at 2008-02-01 10:08:10 (846 săptămâni în urmă) - [Link]Top
ipfw show

firewall log


Mesaj util ?   Da   0 puncte

1
<< Precedenta      Următoarea >>

Forum Index > Open Source > Помогите с natd


Navigare rapidă:


Comunitatea digitală din Moldova. Să adunăm și să organizăm conținutul autohton de pe întreg internet pe un singur site web.